Configuration of service pods for logical router
Abstract
Some embodiments provide a method for configuring a first Pod in a container cluster to perform layer 7 (L7) services for a logical router. At a second Pod that performs logical forwarding operations for the logical router, the method receives configuration data for the logical router from a network management system that defines a logical network for which the logical router routes data messages and performs L7 services. The method provides a set of Pod definition data to a cluster controller to create the first Pod. After creation of the first Pod, the method provides to the first Pod (i) networking information to enable a connection between the first and second Pods and (ii) configuration data defining the L7 services for the first Pod to perform the L7 services on data traffic sent from the second Pod to the first Pod.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method for configuring a first Pod in a container cluster to perform layer 7 (L7) services for a logical router, the method comprising:
at a second Pod that performs logical forwarding operations for the logical router:
from a network management system that defines a logical network for which the logical router routes data messages and performs L7 services, receiving configuration data for the logical router;
providing a set of Pod definition data to a cluster controller to create the first Pod; and
after creation of the first Pod, providing to the first Pod (i) networking information to enable a connection between the first and second Pods and (ii) configuration data defining the L7 services for the first Pod to perform the L7 services on data traffic sent from the second Pod to the first Pod.
2 . The method of claim 1 , wherein the second Pod performs logical forwarding operations for a plurality of different logical routers.
3 . The method of claim 2 , wherein the first Pod performs L7 services for a single one of the plurality of logical routers.
4 . The method of claim 2 , wherein for each logical router, at least one additional Pod performs L7 services.
5 . The method of claim 2 , wherein the set of Pod definition data is a first set of Pod definition data, the method further comprising, at the second Pod:
from the network management system, receiving configuration data for a second one of the plurality of logical routers; providing a second set of Pod definition data to the cluster controller to create a third Pod to perform L7 services for the second logical router; and after creation of the third Pod, providing to the third Pod (i) networking information to enable a connection between the first and third Pods and (ii) configuration data defining the second logical router L7 services for the third Pod to perform said second logical router L7 services on data traffic sent from the second Pod to the third Pod.
6 . The method of claim 1 , wherein the set of Pod definition data is a first set of Pod definition data, the method further comprising:
determining that a third Pod is needed in addition to the second Pod to also perform the L7 services for the logical router; providing a second set of Pod definition data to the cluster controller to create the third Pod; and after creation of the third Pod, providing to the third Pod (i) networking information to enable a connection between the first and third Pods and (ii) configuration data defining the second logical router L7 services for the third Pod to perform said second logical router L7 services on data traffic sent from the second Pod to the third Pod.
7 . The method of claim 1 , wherein the second Pod stores a configuration database to which the network management system provides the configuration data for the first logical router.
8 . The method of claim 7 , wherein:
the second Pod executes a network management system agent and a datapath; and the network management system agent reads logical forwarding configuration data for the logical router from the configuration database and uses the logical forwarding configuration data to configure the datapath to perform the logical forwarding operations for the logical router.
9 . The method of claim 8 , wherein the logical forwarding operations comprise forwarding at least a subset of data traffic received by the logical router to the first Pod for L7 service processing.
10 . The method of claim 9 , wherein the logical forwarding operations further comprise forwarding data traffic received back from the first Pod after the L7 service processing.
11 . The method of claim 9 , wherein the subset of data traffic is forwarded to the first Pod via the connection between the first and second Pods that is enabled by the networking information provided to the first Pod.
12 . The method of claim 7 , wherein:
the second Pod executes an agent for configuring Pods to perform L7 services for the logical router; and the agent communicates with the cluster controller to provide the set of Pod definition data based on the configuration data from the configuration database.
13 . The method of claim 12 , wherein the agent provides the networking information to the first Pod to enable the connection between the first and second Pods.
14 . The method of claim 12 , wherein the first Pod executes a database client to retrieve the configuration data defining the L7 services from the configuration database on the second Pod.
15 . The method of claim 1 , wherein providing the set of Pod definition data comprises:
generating a yaml file to define specifications for the first Pod; and calling a cluster API server to create the first Pod based on the generated yaml file.
16 . The method of claim 1 , wherein the first and second Pods execute on different nodes of the cluster.
17 . The method of claim 1 , wherein the first and second Pods execute on a same node of the cluster.
18 . A non-transitory machine-readable medium storing a program which when executed by at least one processing unit configures a first Pod in a container cluster to perform layer 7 (L7) services for a logical router, the program executing within a second Pod that performs logical forwarding operations for the logical router, the program comprising sets of instructions for:
from a network management system that defines a logical network for which the logical router routes data messages and performs L7 services, receiving configuration data for the logical router; providing a set of Pod definition data to a cluster controller to create the first Pod; and after creation of the first Pod, providing to the first Pod (i) networking information to enable a connection between the first and second Pods and (ii) configuration data defining the L7 services for the first Pod to perform the L7 services on data traffic sent from the second Pod to the first Pod.
19 . The non-transitory machine-readable medium of claim 18 , wherein:
the second Pod performs logical forwarding operations for a plurality of different logical routers; the first Pod performs L7 services for a single one of the plurality of logical routers.
20 . The non-transitory machine-readable medium of claim 18 , wherein the set of Pod definition data is a first set of Pod definition data, the program further comprising sets of instructions for:
determining that a third Pod is needed in addition to the second Pod to also perform the L7 services for the logical router; providing a second set of Pod definition data to the cluster controller to create the third Pod; and after creation of the third Pod, providing to the third Pod (i) networking information to enable a connection between the first and third Pods and (ii) configuration data defining the second logical router L7 services for the third Pod to perform said second logical router L7 services on data traffic sent from the second Pod to the third Pod.
21 . The non-transitory machine-readable medium of claim 18 , wherein:
the second Pod executes a network management system agent and a datapath; the second Pod stores a configuration database to which the network management system provides the configuration data for the first logical router; and the network management system agent reads logical forwarding configuration data for the logical router from the configuration database and uses the logical forwarding configuration data to configure the datapath to perform the logical forwarding operations for the logical router.
22 . The non-transitory machine-readable medium of claim 21 , wherein the logical forwarding operations comprise (i) forwarding at least a subset of data traffic received by the logical router to the first Pod for L7 service processing and (ii) forwarding data traffic received back from the first Pod after the L7 service processing.
23 . The non-transitory machine-readable medium of claim 21 , wherein the first Pod executes a database client to retrieve configuration data defining the L7 services from the configuration database on the second Pod.
24 . The non-transitory machine-readable medium of claim 18 , wherein the set of instructions for providing the set of Pod definition data comprises sets of instructions for:
generating a yaml file to define specifications for the first Pod; and calling a cluster API server to create the first Pod based on the generated yaml file.Join the waitlist — get patent alerts
Track US2025036437A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.